Description
OpenClaw before 2026.4.22 contains a webhook secret revocation bypass vulnerability allowing callers with old Slack and Zalo webhook secrets to remain active after secrets.reload. Attackers can exploit the stale-secret window to deliver webhook events after operator-expected secret revocation, potentially accepting previous credentials.
Problem types
Insufficient Session Expiration
Product status
Any version before 2026.4.22
2026.4.22 (semver)
Credits
侯海飞 (@feynman-hou)
References
github.com/...enclaw/security/advisories/GHSA-275c-xpvc-jgfw (GitHub Security Advisory (GHSA-275c-xpvc-jgfw))
www.vulncheck.com/...et-revocation-bypass-via-secrets-reload (VulnCheck Advisory: OpenClaw < 2026.4.22 - Webhook Secret Revocation Bypass via secrets.reload)